CVE-2024-2182: Ovn: insufficient validation of bfd packets may lead to denial of service

Description

A flaw was found in the Open Virtual Network (OVN). In OVN clusters where BFD is used between hypervisors for high availability, an attacker can inject specially crafted BFD packets from inside unprivileged workloads, including virtual machines or containers, that can trigger a denial of service.

Classification

CVE ID: CVE-2024-2182

Problem Types

Origin Validation Error

Affected Products

Vendor: , Red Hat

Product: , Fast Datapath for Red Hat Enterprise Linux 8, Fast Datapath for Red Hat Enterprise Linux 8, Fast Datapath for Red Hat Enterprise Linux 8, Fast Datapath for Red Hat Enterprise Linux 8, Fast Datapath for Red Hat Enterprise Linux 8, Fast Datapath for Red Hat Enterprise Linux 9, Fast Datapath for Red Hat Enterprise Linux 9, Fast Datapath for Red Hat Enterprise Linux 9, Fast Datapath for Red Hat Enterprise Linux 9, Fast Datapath for Red Hat Enterprise Linux 9, Fast Datapath for RHEL 7, Fast Datapath for RHEL 7, Fast Datapath for RHEL 7, Fast Datapath for RHEL 8, Fast Datapath for RHEL 8, Fast Datapath for RHEL 8, Fast Datapath for RHEL 8, Fast Datapath for RHEL 8, Fast Datapath for RHEL 9, Fast Datapath for RHEL 9, Fast Datapath for RHEL 9

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.36% (probability of being exploited)

EPSS Percentile: 57.07% (scored less or equal to compared to others)

EPSS Date: 2025-04-21 (when was this score calculated)

Stakeholder-Specific Vulnerability Categorization (SSVC)

SSVC Exploitation: none

SSVC Technical Impact: partial

SSVC Automatable: false

References

https://nvd.nist.gov/vuln/detail/CVE-2024-2182
https://access.redhat.com/errata/RHSA-2024:1385
https://access.redhat.com/errata/RHSA-2024:1386
https://access.redhat.com/errata/RHSA-2024:1387
https://access.redhat.com/errata/RHSA-2024:1388
https://access.redhat.com/errata/RHSA-2024:1390
https://access.redhat.com/errata/RHSA-2024:1391
https://access.redhat.com/errata/RHSA-2024:1392
https://access.redhat.com/errata/RHSA-2024:1393
https://access.redhat.com/errata/RHSA-2024:1394
https://access.redhat.com/errata/RHSA-2024:4035
https://access.redhat.com/security/cve/CVE-2024-2182
https://bugzilla.redhat.com/show_bug.cgi?id=2267840
https://mail.openvswitch.org/pipermail/ovs-announce/2024-March/000346.html
https://www.openwall.com/lists/oss-security/2024/03/12/5

Timeline